URL:

https://api.keyser-dashboard.com/loader

Full analysis: https://app.any.run/tasks/3aa51f7e-229d-4ba6-a150-455a6f3a4ce8
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 09, 2026, 17:36:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MD5:

657D7A61CFF47368DF24FED96A9181A6

SHA1:

ED98A14797B862AC3A49D31E228CFC7C260634EC

SHA256:

B4A5F5330E2FB49D62A51D2D5D2AA168F27E82FC44073259EB28B7CF90873670

SSDEEP:

3:N8DLz6EtGVEw:2XzvtSV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • dxwebsetup.exe (PID: 6272)
    • Executing a file with an untrusted certificate

      • infinst.exe (PID: 1068)
      • infinst.exe (PID: 4636)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 6244)
      • infinst.exe (PID: 7572)
      • infinst.exe (PID: 7772)
      • infinst.exe (PID: 7844)
      • infinst.exe (PID: 3272)
      • infinst.exe (PID: 8052)
      • infinst.exe (PID: 8404)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 7296)
      • infinst.exe (PID: 8464)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 7628)
      • infinst.exe (PID: 8232)
      • infinst.exe (PID: 7748)
      • infinst.exe (PID: 7888)
      • infinst.exe (PID: 9152)
      • infinst.exe (PID: 8408)
      • infinst.exe (PID: 7348)
      • infinst.exe (PID: 2452)
      • infinst.exe (PID: 6392)
      • infinst.exe (PID: 8324)
      • infinst.exe (PID: 4120)
      • infinst.exe (PID: 9136)
      • infinst.exe (PID: 8488)
      • infinst.exe (PID: 4020)
      • infinst.exe (PID: 1136)
      • infinst.exe (PID: 9168)
      • infinst.exe (PID: 9040)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 7460)
      • infinst.exe (PID: 7400)
      • infinst.exe (PID: 8736)
      • infinst.exe (PID: 7520)
      • infinst.exe (PID: 8688)
      • infinst.exe (PID: 8472)
      • infinst.exe (PID: 1700)
      • infinst.exe (PID: 8636)
      • infinst.exe (PID: 8748)
      • infinst.exe (PID: 8480)
      • infinst.exe (PID: 5704)
      • infinst.exe (PID: 6532)
      • infinst.exe (PID: 2284)
      • infinst.exe (PID: 3064)
      • infinst.exe (PID: 8256)
      • infinst.exe (PID: 8440)
      • infinst.exe (PID: 8912)
      • infinst.exe (PID: 7508)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 2212)
      • infinst.exe (PID: 2708)
      • infinst.exe (PID: 7788)
      • infinst.exe (PID: 7780)
      • infinst.exe (PID: 8360)
      • infinst.exe (PID: 2364)
      • infinst.exe (PID: 3400)
      • infinst.exe (PID: 4088)
      • infinst.exe (PID: 8916)
      • infinst.exe (PID: 7852)
      • infinst.exe (PID: 1344)
      • infinst.exe (PID: 7072)
      • infinst.exe (PID: 8700)
      • infinst.exe (PID: 7068)
      • infinst.exe (PID: 2992)
      • infinst.exe (PID: 8272)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 8364)
      • infinst.exe (PID: 8420)
    • Registers / Runs the DLL via REGSVR32.EXE

      • dxwsetup.exe (PID: 752)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • dxwsetup.exe (PID: 752)
    • Process drops legitimate windows executable

      • dxwebsetup.exe (PID: 6272)
      • firefox.exe (PID: 8292)
      • dxwsetup.exe (PID: 752)
      • infinst.exe (PID: 1068)
      • infinst.exe (PID: 4636)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 6244)
      • infinst.exe (PID: 7772)
      • infinst.exe (PID: 7572)
      • infinst.exe (PID: 7844)
      • infinst.exe (PID: 3272)
      • infinst.exe (PID: 8404)
      • infinst.exe (PID: 8052)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 7296)
      • infinst.exe (PID: 8464)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 7628)
      • infinst.exe (PID: 8232)
      • infinst.exe (PID: 7748)
      • infinst.exe (PID: 7888)
      • infinst.exe (PID: 9152)
      • infinst.exe (PID: 8408)
      • infinst.exe (PID: 7348)
      • infinst.exe (PID: 2452)
      • infinst.exe (PID: 6392)
      • infinst.exe (PID: 8324)
      • infinst.exe (PID: 4120)
      • infinst.exe (PID: 9136)
      • infinst.exe (PID: 8488)
      • infinst.exe (PID: 4020)
      • infinst.exe (PID: 1136)
      • infinst.exe (PID: 9168)
      • infinst.exe (PID: 9040)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 7460)
      • infinst.exe (PID: 7400)
      • infinst.exe (PID: 8736)
      • infinst.exe (PID: 7520)
      • infinst.exe (PID: 8688)
      • infinst.exe (PID: 1700)
      • infinst.exe (PID: 8636)
      • infinst.exe (PID: 8472)
      • infinst.exe (PID: 8748)
      • infinst.exe (PID: 8480)
      • infinst.exe (PID: 5704)
      • infinst.exe (PID: 6532)
      • infinst.exe (PID: 2284)
      • infinst.exe (PID: 3064)
      • infinst.exe (PID: 8256)
      • infinst.exe (PID: 8440)
      • infinst.exe (PID: 8912)
      • infinst.exe (PID: 7508)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 2212)
      • infinst.exe (PID: 2708)
      • infinst.exe (PID: 7788)
      • infinst.exe (PID: 7780)
      • infinst.exe (PID: 8360)
      • infinst.exe (PID: 2364)
      • infinst.exe (PID: 3400)
      • infinst.exe (PID: 4088)
      • infinst.exe (PID: 8916)
      • infinst.exe (PID: 7852)
      • infinst.exe (PID: 1344)
      • infinst.exe (PID: 7072)
      • infinst.exe (PID: 8700)
      • infinst.exe (PID: 7068)
      • infinst.exe (PID: 2992)
      • infinst.exe (PID: 8272)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 8364)
      • infinst.exe (PID: 8420)
    • Executable content was dropped or overwritten

      • dxwebsetup.exe (PID: 6272)
      • dxwsetup.exe (PID: 752)
      • infinst.exe (PID: 4636)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1068)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 6244)
      • infinst.exe (PID: 7772)
      • infinst.exe (PID: 7572)
      • infinst.exe (PID: 7844)
      • infinst.exe (PID: 3272)
      • infinst.exe (PID: 8404)
      • infinst.exe (PID: 8052)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 7296)
      • infinst.exe (PID: 8464)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 7628)
      • infinst.exe (PID: 7748)
      • infinst.exe (PID: 8232)
      • infinst.exe (PID: 7888)
      • infinst.exe (PID: 9152)
      • infinst.exe (PID: 8408)
      • infinst.exe (PID: 2452)
      • infinst.exe (PID: 7348)
      • infinst.exe (PID: 6392)
      • infinst.exe (PID: 8324)
      • infinst.exe (PID: 4120)
      • infinst.exe (PID: 9136)
      • infinst.exe (PID: 4020)
      • infinst.exe (PID: 8488)
      • infinst.exe (PID: 1136)
      • infinst.exe (PID: 9168)
      • infinst.exe (PID: 9040)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 7460)
      • infinst.exe (PID: 7400)
      • infinst.exe (PID: 8736)
      • infinst.exe (PID: 7520)
      • infinst.exe (PID: 8688)
      • infinst.exe (PID: 8472)
      • infinst.exe (PID: 1700)
      • infinst.exe (PID: 8636)
      • infinst.exe (PID: 8748)
      • infinst.exe (PID: 8480)
      • infinst.exe (PID: 5704)
      • infinst.exe (PID: 6532)
      • infinst.exe (PID: 2284)
      • infinst.exe (PID: 3064)
      • infinst.exe (PID: 8256)
      • infinst.exe (PID: 8440)
      • infinst.exe (PID: 8912)
      • infinst.exe (PID: 7508)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 2212)
      • infinst.exe (PID: 2708)
      • infinst.exe (PID: 7788)
      • infinst.exe (PID: 7780)
      • infinst.exe (PID: 8360)
      • infinst.exe (PID: 2364)
      • infinst.exe (PID: 3400)
      • infinst.exe (PID: 4088)
      • infinst.exe (PID: 8916)
      • infinst.exe (PID: 7852)
      • infinst.exe (PID: 1344)
      • infinst.exe (PID: 7072)
      • infinst.exe (PID: 8700)
      • infinst.exe (PID: 7068)
      • infinst.exe (PID: 2992)
      • infinst.exe (PID: 8272)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 8364)
      • infinst.exe (PID: 8420)
    • Reads security settings of Internet Explorer

      • dxwsetup.exe (PID: 752)
    • Executes as Windows Service

      • VSSVC.exe (PID: 4688)
    • Write to the desktop.ini file (may be used to cloak folders)

      • dxwsetup.exe (PID: 752)
    • Searches for installed software

      • dllhost.exe (PID: 6728)
    • Creates/Modifies COM task schedule object

      • dxwsetup.exe (PID: 752)
      • regsvr32.exe (PID: 6320)
      • regsvr32.exe (PID: 5224)
      • regsvr32.exe (PID: 4516)
      • regsvr32.exe (PID: 8104)
      • regsvr32.exe (PID: 8468)
      • regsvr32.exe (PID: 7384)
      • regsvr32.exe (PID: 8268)
      • regsvr32.exe (PID: 9124)
      • regsvr32.exe (PID: 4572)
      • regsvr32.exe (PID: 7900)
      • regsvr32.exe (PID: 8252)
      • regsvr32.exe (PID: 1976)
      • regsvr32.exe (PID: 8664)
      • regsvr32.exe (PID: 8588)
      • regsvr32.exe (PID: 8652)
      • regsvr32.exe (PID: 6820)
      • regsvr32.exe (PID: 4144)
      • regsvr32.exe (PID: 9080)
      • regsvr32.exe (PID: 6096)
      • regsvr32.exe (PID: 6572)
      • regsvr32.exe (PID: 8428)
      • regsvr32.exe (PID: 9100)
      • regsvr32.exe (PID: 6488)
      • regsvr32.exe (PID: 5828)
      • regsvr32.exe (PID: 3172)
      • regsvr32.exe (PID: 8212)
      • regsvr32.exe (PID: 7804)
    • Executes application which crashes

      • loader.exe (PID: 7360)
      • loader.exe (PID: 8000)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 7632)
      • firefox.exe (PID: 8320)
      • firefox.exe (PID: 8292)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7972)
      • msedge.exe (PID: 7632)
      • firefox.exe (PID: 8292)
    • Reads Environment values

      • identity_helper.exe (PID: 3380)
    • Reads the computer name

      • identity_helper.exe (PID: 3380)
      • TextInputHost.exe (PID: 8372)
      • dxwsetup.exe (PID: 752)
      • loader.exe (PID: 7360)
      • loader.exe (PID: 8000)
    • Checks supported languages

      • identity_helper.exe (PID: 3380)
      • dxwebsetup.exe (PID: 6272)
      • dxwsetup.exe (PID: 752)
      • TextInputHost.exe (PID: 8372)
      • infinst.exe (PID: 4636)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1068)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 6244)
      • infinst.exe (PID: 7572)
      • infinst.exe (PID: 7772)
      • infinst.exe (PID: 7844)
      • infinst.exe (PID: 8404)
      • infinst.exe (PID: 3272)
      • infinst.exe (PID: 8052)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 8464)
      • infinst.exe (PID: 7296)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 7628)
      • infinst.exe (PID: 8232)
      • infinst.exe (PID: 7748)
      • infinst.exe (PID: 7888)
      • infinst.exe (PID: 8408)
      • infinst.exe (PID: 9152)
      • infinst.exe (PID: 7348)
      • infinst.exe (PID: 2452)
      • infinst.exe (PID: 6392)
      • infinst.exe (PID: 8324)
      • infinst.exe (PID: 4120)
      • infinst.exe (PID: 9136)
      • infinst.exe (PID: 8488)
      • infinst.exe (PID: 4020)
      • infinst.exe (PID: 1136)
      • infinst.exe (PID: 9168)
      • infinst.exe (PID: 9040)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 7460)
      • infinst.exe (PID: 7400)
      • infinst.exe (PID: 8736)
      • infinst.exe (PID: 7520)
      • infinst.exe (PID: 8688)
      • infinst.exe (PID: 8472)
      • infinst.exe (PID: 1700)
      • infinst.exe (PID: 8636)
      • infinst.exe (PID: 8748)
      • infinst.exe (PID: 8480)
      • infinst.exe (PID: 5704)
      • infinst.exe (PID: 6532)
      • infinst.exe (PID: 2284)
      • infinst.exe (PID: 3064)
      • infinst.exe (PID: 8256)
      • infinst.exe (PID: 8440)
      • infinst.exe (PID: 8912)
      • infinst.exe (PID: 7508)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 2212)
      • infinst.exe (PID: 2708)
      • infinst.exe (PID: 7788)
      • infinst.exe (PID: 7780)
      • infinst.exe (PID: 8360)
      • infinst.exe (PID: 2364)
      • infinst.exe (PID: 3400)
      • infinst.exe (PID: 4088)
      • infinst.exe (PID: 8916)
      • infinst.exe (PID: 7852)
      • infinst.exe (PID: 1344)
      • infinst.exe (PID: 8700)
      • infinst.exe (PID: 7068)
      • infinst.exe (PID: 2992)
      • infinst.exe (PID: 8272)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 8364)
      • infinst.exe (PID: 8420)
      • loader.exe (PID: 7360)
      • loader.exe (PID: 8000)
      • infinst.exe (PID: 7072)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 7632)
      • firefox.exe (PID: 8292)
    • Manual execution by a user

      • loader.exe (PID: 8952)
      • loader.exe (PID: 9000)
      • firefox.exe (PID: 8320)
      • loader.exe (PID: 4280)
      • loader.exe (PID: 8308)
      • Taskmgr.exe (PID: 4940)
      • Taskmgr.exe (PID: 6084)
      • mspaint.exe (PID: 7512)
      • loader.exe (PID: 7360)
      • loader.exe (PID: 7992)
      • loader.exe (PID: 2140)
      • loader.exe (PID: 8000)
    • Create files in a temporary directory

      • dxwebsetup.exe (PID: 6272)
      • dxwsetup.exe (PID: 752)
      • mspaint.exe (PID: 7512)
    • The sample compiled with english language support

      • dxwebsetup.exe (PID: 6272)
      • firefox.exe (PID: 8292)
      • dxwsetup.exe (PID: 752)
      • infinst.exe (PID: 4636)
      • infinst.exe (PID: 4228)
      • infinst.exe (PID: 1068)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 6244)
      • infinst.exe (PID: 7772)
      • infinst.exe (PID: 7572)
      • infinst.exe (PID: 7844)
      • infinst.exe (PID: 3272)
      • infinst.exe (PID: 8404)
      • infinst.exe (PID: 8052)
      • infinst.exe (PID: 8164)
      • infinst.exe (PID: 7296)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 8464)
      • infinst.exe (PID: 8232)
      • infinst.exe (PID: 7628)
      • infinst.exe (PID: 7748)
      • infinst.exe (PID: 7888)
      • infinst.exe (PID: 9152)
      • infinst.exe (PID: 7348)
      • infinst.exe (PID: 8408)
      • infinst.exe (PID: 2452)
      • infinst.exe (PID: 8324)
      • infinst.exe (PID: 6392)
      • infinst.exe (PID: 4120)
      • infinst.exe (PID: 9136)
      • infinst.exe (PID: 8488)
      • infinst.exe (PID: 4020)
      • infinst.exe (PID: 1136)
      • infinst.exe (PID: 9168)
      • infinst.exe (PID: 9040)
      • infinst.exe (PID: 7548)
      • infinst.exe (PID: 7460)
      • infinst.exe (PID: 7400)
      • infinst.exe (PID: 8736)
      • infinst.exe (PID: 7520)
      • infinst.exe (PID: 8688)
      • infinst.exe (PID: 8472)
      • infinst.exe (PID: 1700)
      • infinst.exe (PID: 8636)
      • infinst.exe (PID: 8748)
      • infinst.exe (PID: 8480)
      • infinst.exe (PID: 5704)
      • infinst.exe (PID: 6532)
      • infinst.exe (PID: 2284)
      • infinst.exe (PID: 3064)
      • infinst.exe (PID: 8256)
      • infinst.exe (PID: 8440)
      • infinst.exe (PID: 8912)
      • infinst.exe (PID: 7508)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 2212)
      • infinst.exe (PID: 2708)
      • infinst.exe (PID: 7788)
      • infinst.exe (PID: 7780)
      • infinst.exe (PID: 8360)
      • infinst.exe (PID: 2364)
      • infinst.exe (PID: 3400)
      • infinst.exe (PID: 4088)
      • infinst.exe (PID: 8916)
      • infinst.exe (PID: 7852)
      • infinst.exe (PID: 1344)
      • infinst.exe (PID: 7072)
      • infinst.exe (PID: 8700)
      • infinst.exe (PID: 7068)
      • infinst.exe (PID: 2992)
      • infinst.exe (PID: 8272)
      • infinst.exe (PID: 8656)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 8364)
      • infinst.exe (PID: 8420)
    • Launching a file from a Registry key

      • dxwebsetup.exe (PID: 6272)
    • Creates files or folders in the user directory

      • dxwsetup.exe (PID: 752)
      • WerFault.exe (PID: 7744)
    • Reads the machine GUID from the registry

      • dxwsetup.exe (PID: 752)
      • loader.exe (PID: 7360)
      • loader.exe (PID: 8000)
    • Checks proxy server information

      • slui.exe (PID: 7372)
      • dxwsetup.exe (PID: 752)
      • WerFault.exe (PID: 7744)
      • WerFault.exe (PID: 2452)
    • Creating file in SysWOW64

      • dxwsetup.exe (PID: 752)
    • Manages system restore points

      • SrTasks.exe (PID: 8272)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 6084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
324
Monitored processes
160
Malicious processes
78
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs loader.exe no specs loader.exe loader.exe no specs loader.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs textinputhost.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs dxwebsetup.exe no specs dxwebsetup.exe dxwsetup.exe slui.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe taskmgr.exe no specs taskmgr.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe mspaint.exe no specs infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs SPPSurrogate no specs loader.exe no specs loader.exe werfault.exe loader.exe no specs loader.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
752C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
dxwebsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DirectX Setup
Exit code:
2852126720
Version:
4.9.0.0904
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
792"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 4168 -prefsLen 45063 -prefMapHandle 4172 -prefMapSize 273045 -jsInitHandle 4176 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 4140 -initialChannelId {27b666cf-384f-461a-a439-129a1ac75869} -parentPid 8292 -crashReporter "\\.\pipe\gecko-crash-server-pipe.8292" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 5 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140_1.dll
1068C:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe d3dx9_24_x64.infC:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxc7a3.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1136C:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe X3DAudio1_2_x64.infC:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxc7a3.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1344C:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe X3DAudio1_7_x64.infC:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxc7a3.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1700C:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe XACT3_1_x64.infC:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxc7a3.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1976C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\xactengine3_0.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2140"C:\Users\admin\Downloads\loader.exe" C:\Users\admin\Downloads\loader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\loader.exe
c:\windows\system32\ntdll.dll
2212C:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe XAudio2_4_x64.infC:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxc7a3.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2284C:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe X3DAudio1_5_x64.infC:\Users\admin\AppData\Local\Temp\DXC7A3.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxc7a3.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
30 031
Read events
29 681
Write events
322
Delete events
28

Modification events

(PID) Process:(6272) dxwebsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:wextract_cleanup0
Value:
rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
(PID) Process:(752) dxwsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(752) dxwsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(752) dxwsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(752) dxwsetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000E72A10D38E81DC01F002000074220000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6728) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000007B896FD38E81DC01481A0000C81D0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6728) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000007B896FD38E81DC01481A0000C81D0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6728) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000007B896FD38E81DC01481A0000C81D0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6728) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000114E74D38E81DC01481A0000C81D0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6728) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000E72A10D38E81DC01481A0000C81D0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
649
Suspicious files
1 318
Text files
345
Unknown types
46

Dropped files

PID
Process
Filename
Type
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFfdd18.TMP
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFfdd28.TMP
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFfdd28.TMP
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFfdd37.TMP
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFfdd28.TMP
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7632msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
662
TCP/UDP connections
185
DNS requests
257
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7972
msedge.exe
GET
304
150.171.27.11:443
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
US
whitelisted
7972
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1741678270&lafgdate=0
US
text
768 b
whitelisted
7972
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
446 b
whitelisted
7972
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:RCZpix_xRdT40pONaz_jazv2Ud4JuR9OlGpK93aCfuo&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
101 b
whitelisted
7972
msedge.exe
GET
200
104.21.68.86:443
https://api.keyser-dashboard.com/loader
US
executable
128 Kb
unknown
7972
msedge.exe
GET
200
2.16.204.156:443
https://www.bing.com/api/shopping/v1/user/shoppingsettings?EnabledServiceFeaturesv2=edgeServerUX.shopping.cashbackCloseSnooze,edgeServerUX.shopping.cashbackEUMarkets,edgeServerUX.shopping.enableFooterForAllNotifications,edgeServerUX.shopping.merchantAbTestingCf,edgeServerUX.shopping.msEdgeShoppingCashbackDismissTimeout2s,edgeServerUX.shopping.ppNewUser,edgeServerUX.shopping.zeroSuccessSkip
NL
text
1.02 Kb
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
1600
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
7972
msedge.exe
GET
200
150.171.28.11:443
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
US
text
266 b
whitelisted
7972
msedge.exe
POST
200
142.250.185.195:443
https://update.googleapis.com/service/update2/json?cup2key=14:XPgzs4KEBPIH3bo_YMMZcxjUPiWjrK34i8YzJlM6cb8&cup2hreq=47d08dfae6e87283993de37d636b5e16f2dfcb1aefffe9579081a538b3e42dc2
US
text
889 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
1600
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3304
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7972
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7972
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7972
msedge.exe
104.21.68.86:443
api.keyser-dashboard.com
CLOUDFLARENET
US
whitelisted
7972
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7972
msedge.exe
104.18.23.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.251.141.110
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
api.keyser-dashboard.com
  • 104.21.68.86
  • 172.67.192.124
unknown
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
update.googleapis.com
  • 142.250.185.195
whitelisted
www.bing.com
  • 2.16.204.156
  • 2.16.204.155
  • 2.16.204.150
  • 2.16.204.160
  • 2.16.204.151
  • 2.16.204.158
  • 2.16.204.149
  • 2.16.204.152
  • 2.16.204.148
whitelisted
clients2.googleusercontent.com
  • 142.250.186.97
whitelisted
edgeassetservice.azureedge.net
  • 13.107.246.44
  • 13.107.213.44
whitelisted

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Attached HTTP
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Attached HTTP
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH